analysis riskware policy fe-rules enable

Prev Next

Globally enables or disables riskware detection based on the set of Trellix common rules on the EX Series appliance only.

When this command is enabled, email that matches a Trellix common riskware rule will generate an alert notification. You can view the analysis results on the eAlerts > Riskware page of the Web UI.

Note

Riskware detection based on the set of Trellix common rules is enabled by default. When it is disabled, the following warning message is displayed:

The rules are now disabled. FireEye recommends re-enabling these rules for security reasons.

Note

This command replaces the deprecated analysis riskware policy enable command introduced in Release 8.0.

Syntax

[no] analysis riskware policy fe-rules enable

Parameters

no

Use the no form of this command to globally disable riskware detection based on the set of Trellix common rules on the EX Series appliance.

Example

The following example enables riskware detection based on the set of Trellix common rules on the EX Series appliance:

hostname (config) # analysis riskware policy fe-rules enable

The following example disables riskware detection for Trellix rules on the EX Series appliance:

hostname (config) # no analysis riskware policy fe-rules enable

User role

Admin or Operator

Command mode

Config

Supported appliances

This command is supported on the following appliances running the specified releases or later:

  • Email Security — Server: Release 8.4.1